SEU-resistant SHA-256 design for security in satellites
Bibliographic record
Abstract
Satellites currently play a fundamental role in communications and are also used in modern military operations. Given their importance, satellites should not rely their security on the uniqueness and obscurity of their systems. However, it is not trivial to implement cryptographic mechanisms due to high energy particles coming from space, which are the main cause of single event upsets (SEUs). Therefore, besides stringent constraints on area, power, energy and performance, satellites architectures must provide SEU-resistance. This research proposes and analyzes various architectures for SHA-256 hash function which are of utmost importance to ensure secure communications. Furthermore, in contrast to previous work, the proposed architectures are able to detect and correct errors. We show that a scheme employing Hamming codes to protect the main registers of SHA-256 leads to a better trade-off in terms of area, performance and power consumption, compared to the traditional triple modular redundancy (TMR). When implemented on an Altera Cyclone II FPGA, this approach demands 3657 LEs and consumes 126.18 mW of dynamic power. This can be translated to the utilization of 2.3 times as much area and 1.5 times as much power as the non-fault tolerant SHA-256 implementation. These results are crucial for supporting present and future embedded security in satellites, which demand both highly constrained and SEU-resistant designs.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.001 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.001 | 0.000 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.001 |
| Open science | 0.001 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.003 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".